vendor:
LTris
by:
zillionATsafemode.org
7.2
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: LTris
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD
2002
LTris Memory Corruption Vulnerability
A memory corruption vulnerability has been reported for LTris that may result in a local attacker obtaining group 'games' privileges. The exploit code is written in Perl and contains a shellcode that is 520 bytes long. The exploit code sets the environment variable 'HOME' to the buffer containing the shellcode and executes the vulnerable application 'ltris'.
Mitigation:
No known mitigation or remediation is available for this vulnerability.